sk83520 - How to verify that Security Gateway and/or Security Management Server can access Check Point servers?
How to verify that Security Gateway and/or Security Management Server can access Check Point servers?
Solution
Security Gateways and Security Management Server require access to the Internet (either directly, or via configured proxy) for various Software Blades.
Important Notes:
- Make sure the Access Control Policy for Security Gateways does not drop / block the connections to the required Check Point servers.
If you disabled the default Implied Rules, then you must follow sk179346 - Configuring Explicit Rules instead of Implied Rules.
Make sure the NAT Policy for Security Gateways does not translate the connections to the required Check Point servers.
In Gaia OS, use the "
curl_cli" command.
Notes:
- To configure proxy settings, do one of these:
- Configure the proxy server locally in Gaia OS settings as described in the Gaia Administration Guide for your version > chapter "System Management" > section "Proxy".
- Configure the proxy server in SmartConsole:
- In Menu > option "Global properties" > page "Proxy" (applies to all objects).
- In the Security Gateway / Management Server object > section "Network Management" > page "Proxy" (overrides the global proxy configuration).
- Refer to sk110779 - "curl: (900) servercert: Error - server certificate validation failed!" when running "curl_cli" command.
- For each of the
curl_clicommands, add the option--cacert $CPDIR/conf/ca-bundle.crtto prevent the issue in sk110779. - In Gaia Embedded OS (all versions), use the "
wget" command.
Notes:
To configure proxy settings, do one of these:
- In the Locally Managed mode and Centrally Managed mode - configure the proxy server locally in Gaia OS settings as described in the Spark Firewall Locally Managed Administration Guide for your version ( R81.10.x, R80.20.x, R77.20.x) > chapter "Managing the Device" > section "Configuring the Proxy Server".
In the Centrally Managed mode only - configure the proxy server in SmartConsole > the Security Gateway object > section "Topology" > page "Proxy" (overrides the proxy settings in SmartConsole > Global Properties > page "Proxy").
If you configured an IPv6 address on an external interface on your Security Gateway / Security Management Server, then the Access Control policy must also allow the IPv6 connections to domains listed below.
All the domains below are part of the new Updatable object "Check Point Services".
For more information about Updatable objects, see sk131852.
- You can also check and subscribe to updates on the Services status page.
The table below lists the relevant connectivity tests.
Enter the string to filter this table:
| Hostname | Protocol | From | Used For (Version) | Verifying Connectivity (Run command listed below. You will get a response if connectivity is OK.) |
cws.checkpoint.com |
http | Security Gateway, Security Management Server, SMB Gateways |
Social Media Widget Detection | curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/APPI/SystemStatus/type/short |
| URL Filtering Cloud Categorization | curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/URLF/SystemStatus/type/short |
|||
| Virus Detection | curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/AntiVirus/SystemStatus/type/short |
|||
| Bot Detection | curl_cli [--proxy <IP_or_HostName:Port>] -v http://cws.checkpoint.com/Malware/SystemStatus/type/short |
|||
updates.checkpoint.com |
https http |
Security Gateway, Security Management Server, Spark Firewall |
IPS Updates, Updatable Object (R80.20 and higher, on Security Gateway and Security Management) |
curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://updates.checkpoint.com/WebService/Monitor |
crl.godaddy.com |
https http |
Security Gateway, Security Management Server |
Update Service uses it for revocation | curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://crl.godaddy.com/ |
crl.globalsign.com |
http | Security Gateway, Security Management Server |
CRL that updates service certificate uses | curl_cli -v http://crl.globalsign.com/ |
dl3.checkpoint.com |
https | Security Gateway, Security Management Server |
Download Service Updates Updatable Object (R80.20 and higher, on Security Gateway and Security Management) |
curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://dl3.checkpoint.com |
usercenter.checkpoint.com |
https | Security Gateway, Security Management Server |
Contract Entitlement for IPS, Traditional Anti-Virus, Legacy URL Filtering | curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://usercenter.checkpoint.com/usercenter/services/productcoverageservice |
usercenter.checkpoint.com |
https | Security Gateway, Security Management Server |
Software Blades Manager Service | curl_cli [--proxy <IP_or_HostName:Port>] -v --cacert $CPDIR/conf/ca-bundle.crt https://usercenter.checkpoint.com/usercenter/services/BladesManagerService |
resolver1.chkp.ctmail.comresolver2.chkp.ctmail.comresolver3.chkp.ctmail.comresolver4.chkp.ctmail.comresolver5.chkp.ctmail.com |
http | Security Gateway | Suspicious Mail Outbreaks | curl_cli [--proxy <IP_or_HostName:Port>] -v http://resolver1.chkp.ctmail.com |
download.ctmail.com |
http | Security Gateway, Security Management Server |
Anti-Spam | curl_cli [--proxy <IP_or_HostName:Port>] -v http://download.ctmail.com |
te.checkpoint.com |
https | Security Gateway | Threat Emulation | curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://te.checkpoint.com/tecloud/Ping |
teadv.checkpoint.com |
https http |
Security Gateway | Threat Emulation | curl_cli [--proxy <IP_or_HostName:Port>] -v http://teadv.checkpoint.com/version.txt |
threat-emulation.checkpoint.com |
https | Security Gateway | Threat Emulation | curl_cli [--proxy <IP_or_HostName:Port>] -v https://threat-emulation.checkpoint.com/tecloud/Ping |
ptcs.checkpoint.comptcd.checkpoint.com |
https | Security Gateway | Private ThreatCloud (PTC) Updates | curl_cli [--proxy <IP_or_HostName:Port>] -v https://ptcs.checkpoint.comcurl_cli [--proxy <IP_or_HostName:Port>] -v https://ptcd.checkpoint.com |
kav8.zonealarm.com |
http | Security Gateway | Archive scanning, Deep inspection |
curl_cli [--proxy <IP_or_HostName:Port>] -v http://kav8.zonealarm.com/version.txt |
kav8.checkpoint.com |
https http |
Security Gateway Endpoint Security Management |
Traditional Anti-Virus, Endpoint Security Management pulling Anti-Malware updates |
curl_cli [--proxy <IP_or_HostName:Port>] -v http://kav8.checkpoint.com/version.txt |
avupdates.checkpoint.com |
https http |
Security Gateway | Traditional Anti-Virus, Legacy URL Filtering |
curl_cli [--proxy <IP_or_HostName:Port>] -v http://avupdates.checkpoint.com/UrlList.txt |
sigcheck.checkpoint.com |
http | Security Gateway, Security Management Server |
Download of signature updates for Traditional Anti-Virus, Legacy URL Filtering, UTM-1 Edge devices | curl_cli [--proxy <IP_or_HostName:Port>] -v http://sigcheck.checkpoint.com/Siglist2.txt |
secureupdates.checkpoint.com |
http | General updates server for Check Point gateways | Manage Security Gateways | curl_cli [--proxy <IP_or_HostName:Port>] -I http://secureupdates.checkpoint.com/IP-list/100k.txt |
productcoverage.checkpoint.com |
https | Security Gateway, Security Management Server |
Makes sure the contracts are up-to-date | curl_cli [--proxy <IP_or_HostName:Port>] -v https://productcoverage.checkpoint.com/productcoverageservice |
sc1.checkpoint.comsc2.checkpoint.comsc3.checkpoint.comsc4.checkpoint.comsc5.checkpoint.com |
https | Security Gateway, Security Management Server, SmartConsole, SmartDashboard |
Download of icons and screenshots from Check Point media storage servers (e.g., Check Point AppWiki) | curl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/sc/images/checkmark.gifcurl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/za/images/facetime/large_png/60342479_lrg.pngcurl_cli [--proxy <IP_or_HostName:Port>] -v https://sc1.checkpoint.com/za/images/facetime/large_png/60096017_lrg.png |
push.checkpoint.com |
https | Mobile Access Gateway | Push Notifications for incoming e-mails and meeting requests on handheld devices, while the Capsule Workspace Mail app is in the background | curl [--proxy <IP_or_HostName:Port>] -v -k https://push.checkpoint.com/push/ping |
downloads.checkpoint.com |
http | Mobile Access Gateway, Security Management Server |
Download of Endpoint Compliance Updates (Endpoint Security On Demand (ESOD) database): |
curl_cli [--proxy <IP_or_HostName:Port>] -v http://downloads.checkpoint.com |
productservices.checkpoint.com |
https | Security Gateway, Security Management Server |
Next Generation Licensing (Entitlement / Licensing Updates) | curl_cli [--proxy <IP_or_HostName:Port>] -v http://productservices.checkpoint.com |
diag-services.checkpoint.com |
https | Security Gateway, Security Management Server |
Core Dump File uploader (Authentication / Upload backend) | curl [--proxy <IP_or_HostName:Port>] -v -k https://diag-services.checkpoint.com |
mercury.ts.checkpoint.comfairfax.ott.checkpoint.comftp-proxy.checkpoint.com |
https | Security Gateway, Security Management Server |
File uploader for CPinfo, CP_Uploader, CPSizeMe (to a server in USA, Canada, Israel) | curl [--proxy <IP_or_HostName:Port>] -v -k mercury.ts.checkpoint.comcurl [--proxy <IP_or_HostName:Port>] -v -k fairfax.ott.checkpoint.comcurl [--proxy <IP_or_HostName:Port>] -v -k ftp-proxy.checkpoint.com |
rep.checkpoint.com |
https | Security Gateway, Security Management Server, Cloud Firewall agents for Kubernetes workloads |
Reputation service | curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://rep.checkpoint.com -X POST -w '\nHTTP Status: %{http_code}\n' |
<Service-Identifier>.maas.checkpoint.com |
https | Smart-1 Cloud service | On-premises Management Server and On-premises Security Gateways connect to the Smart-1 Cloud service | To test connectivity with Smart-1 Cloud deployments in Europe:curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw.portal.checkpoint.comTo test connectivity with Smart-1 Cloud deployments in the United States: curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw-us.portal.checkpoint.comTo test connectivity with Smart-1 Cloud deployments in the APAC: curl_cli [--proxy <IP_or_HostName:Port>] -v cloudinfra-gw.ap.portal.checkpoint.com |
api-cpx.dome9.comapi.dome9.comapi-cpx.eu1.dome9.comapi.eu1.dome9.comapi-cpx.ap2.dome9.comapi.ap2.dome9.comapi-cpx.cace1.dome9.comapi.cace1.dome9.comapi-cpx.ap3.dome9.comapi.ap3.dome9.comapi-cpx.ap1.dome9.comapi.ap1.dome9.com |
https | Cloud Firewall agents for Kubernetes workloads | Cloud Firewall services | curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://api-cpx.dome9.com/namespaces -X POSTcurl_cli [--proxy <IP_or_HostName:Port>] -v -k https://api.dome9.com -X POST -w '\nHTTP Status: %{http_code}\n' -o /dev/null |
shiftleft.portal.checkpoint.comshiftleft-prod-bucket.sg.iaas.checkpoint.comus-gw.sg.iaas.checkpoint.comeu-gw.sg.iaas.checkpoint.comau-gw.sg.iaas.checkpoint.comca-gw.sg.iaas.checkpoint.comin-gw.sg.iaas.checkpoint.comsg-gw.sg.iaas.checkpoint.com |
https | Cloud Firewall agents for Kubernetes workloads | Vulnerability scanner services | curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://shiftleft.portal.checkpoint.com |
*.amazontrust.comocsp.e2m02.amazontrust.comocsp.e2m03.amazontrust.comocsp.e2m04.amazontrust.comcrt.e2m02.amazontrust.comcrt.e2m03.amazontrust.comcrt.e2m04.amazontrust.comcrl.e2m02.amazontrust.comcrl.e2m03.amazontrust.comcrl.e2m04.amazontrust.comocsp.rootca1.amazontrust.comocsp.rootca2.amazontrust.comocsp.rootca3.amazontrust.comocsp.rootca4.amazontrust.comocsp.rootg2.amazontrust.comcrt.rootca1.amazontrust.comcrt.rootca2.amazontrust.comcrt.rootca3.amazontrust.comcrt.rootca4.amazontrust.comcrt.rootg2.amazontrust.comcrl.rootca1.amazontrust.comcrl.rootca2.amazontrust.comcrl.rootca3.amazontrust.comcrl.rootca4.amazontrust.comcrl.rootg2.amazontrust.com |
http | Security Gateway, Security Management Server |
Services in Check Point Portal (formerly, Infinity Portal) | curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN> |
dns.google.com |
icmp | Spark Firewall | Probing | 1. In WebUI, go to "Device" view > "System" section > "Tools" page. 2. Use the Ping tool. |
dns.cloudflare.com |
icmp | Spark Firewall | Probing | 1. In WebUI, go to "Device" view > "System" section > "Tools" page. 2. Use the Ping tool. |
dns.opendns.com |
icmp | Spark Firewall | Probing | 1. In WebUI, go to "Device" view > "System" section > "Tools" page. 2. Use the Ping tool. |
smbcloud-api-gateway.iaas.checkpoint.com |
https | Spark Firewall | Spark Firewall cloud services | curl_cli [--proxy <IP_or_HostName:Port>] -v -k https://smbcloud-api-gateway.iaas.checkpoint.com/health |
*.spark-management.checkpoint.com |
https | Spark Firewall | Spark Management - Spark Firewall activation | curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN> |
*.spark-management.checkpoint.com |
http | Spark Firewall | CRL check | curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN> |
*.portal.checkpoint.com*.in.portal.checkpoint.com |
https | Spark Firewall | Services in Check Point Portal (formerly, Infinity Portal) | curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN> |
*.iaas.checkpoint.com |
https | Spark Firewall | Spark Firewall activation service | curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN> |
*.<Region>.ddnsbox.com |
TCP port 53 | Spark Firewall | Dynamic DNS (DDNS) | curl_cli [--proxy <IP_or_HostName:Port>] -v -k <Specific FQDN> |
zerotouch.checkpoint.com |
https | Spark Firewall | Zero Touch deployment | test zero-touch-request |
smbmgmtservice.checkpoint.com |
https | Spark Firewall | SMP Portal deployment - obsoleted by Spark Management | smp_connectivity_test smbmgmtservice.checkpoint.com |
| See sk179105. Note - These domains are part of the " Check Point Services" Updatable object. |
https | Check Point Portal (formerly, Infinity Portal) | Services in Check Point Portal (formerly, Infinity Portal) | curl_cli [--proxy <IP_or_HostName:Port>] -v -k <URL> |
Additional Notes:
Specific IP addresses for the servers are not provided because they vary by region and are subject to change.
There are some Check Point Services / Software Blades that require Proxy configuration on top of the Proxy global property configured in the object of your Security Management Server / Domain Management Server, so that connections to
sigcheck.checkpoint.comwill be able to pass through your Proxy server.
Show / Hide Examples from R7X SmartDashboard
Note: Check if you have one those blades enabled and configure proxy settings for each of them.
- Endpoint Compliance:
- Go to the "Mobile Access" tab
- Expand the "Endpoint Security On Demand"
- Click on the "Endpoint Compliance Updates"
- In the "Automatic Update" section, click on the "Configure..." button
- Go to the "Proxy" tab
Example:
- Legacy URL Filtering:
- Go to the "Application & URL Filtering" tab
- Expand the "Legacy URL Filtering"
- Click on the "Legacy URL Filtering Policy"
- Click on the "Automatic updates" link
- Go to the "Proxy" tab
Example:
- Traditional Anti-Virus and UTM-1 Edge devices:
- Go to the "Threat Prevention" tab
- Expand the "Traditional Anti-Virus"
- Click on the "Database Updates"
- In the "Automatic Update" section, click on the "Configure..." button
- Go to the "Proxy" tab
Example:
Revision History
| Date | Description |
| 18 May 2025 | Added servers for CPinfo, CP_Uploader, CPSizeMe |
| 10 Jan 2025 | Added the notes about Access Control policy and NAT policy |
| 23 Oct 2024 | Added |
| 14 Apr 2024 | Updated the list for Spark Firewall |
| 01 Nov 2023 | - Added reference to Proxy configuration in the applicable Administration Guides - Added Check Point Portal services (sk179105) |
| 29 May 2017 | Added information about Proxy configuration on top of the Proxy global property configured in the object of Security Management Server / Domain Management Server |
| 25 Apr 2017 | Added http://downloads.checkpoint.com |
| 16 Feb 2017 | Added "Revision History" section |
| 02 Mar 2017 | Added teadv.checkpoint.com |